Windows file
msiexec.exe (Windows Installer): genuine Windows file, or a copy using its name?
msiexec.exe is the Windows Installer, the program that installs, repairs and removes software distributed as .msi packages. The copy in System32 is safe. Attackers both name malware msiexec.exe and use the genuine file to run their own packages, so the folder and the command line matter.
Prefer to check it yourself? The manual checks follow.
msiexec.exe in C:\Windows\System32 (and C:\Windows\SysWOW64 for 32-bit), with Microsoft as the publisher, is safe. It appears in Task Manager only while an installation, repair or removal is running. Do not delete it and do not end it during an install.
The name is used by malware, and the genuine file is also run by attackers to execute malicious packages. Cracks and keygens for pirated software and games are a common way such malware arrives, so install programs only from the publisher's own site.
- Description in the file
- Windows Installer
- Genuine folders
- C:\Windows\System32\msiexec.exe; C:\Windows\SysWOW64\msiexec.exe
- Publisher
- Microsoft Corporation
- Signing in the known builds
- Winbindex lists both signed and unsigned builds among the 93 Microsoft builds, so a missing signature tab alone is not proof of a fake
- Windows releases
- Windows 10 1507 to Windows 11 26H1
- Runs
- Only during an install, repair or removal of an .msi package, or when a program or script starts it
- Related service
- Windows Installer (msiserver)
What Windows Installer does
msiexec.exe is the command-line front end of Windows Installer. It reads an .msi package (or an .msp patch) and installs, modifies, repairs or uninstalls the product it describes. Microsoft documents its options: /i installs, /x uninstalls, /p applies a patch, /f repairs, /quiet and /qn suppress the window, and /L writes a log.
Windows 10 and Windows 11 ship it in System32, with a 32-bit copy in SysWOW64. If the process is ended while an installation runs, that installation fails, and ending it can leave a half-installed program, so leave the genuine process alone.
Because Windows has used it for many years, from Windows XP onward, its name is familiar and trusted, which is why attackers copy it.
About .exe files. An .exe file is a program. It runs as a process you can see in Task Manager, so its name, folder and publisher are what to check.
How to check an msiexec.exe
Three checks need nothing installed.
- Where the file is. Press Ctrl+Shift+Esc, choose More details if needed, right-click msiexec.exe on the Details tab and choose Open file location. The genuine file is in C:\Windows\System32 or C:\Windows\SysWOW64. A copy in a user folder or in AppData\Local\Temp is not Windows.
- Who the publisher is. On the Details tab right-click msiexec.exe, open Properties and read the Details tab: the copyright line should name Microsoft Corporation. A launch prompt from User Account Control that says Publisher: Unknown for msiexec.exe is a reason to decline.
- What it was asked to do. The command line shows which package it is running. A package fetched from a web address, or an unfamiliar .msi in a Temp folder, is the pattern to watch for:
Get-CimInstance Win32_Process -Filter "Name='msiexec.exe'" | Select-Object ProcessId, ParentProcessId, ExecutablePath, CommandLine | Format-List - Compare the file with Microsoft's builds. Use the checker on this page: it computes the SHA-256 in your browser and compares it with the known Microsoft builds.
These checks show whether the file is the Windows one. They cannot show that the genuine file was told to run a malicious package, so look at the command line and run Microsoft Defender's full scan, and the offline scan if the signs below apply.
Check your msiexec.exe
Choose the msiexec.exe you are unsure about. Its SHA-256 checksum is calculated in your browser and compared with the 93 Microsoft builds indexed from Windows releases and updates.
The file stays on your computer. Nothing is uploaded: the checksum is computed locally.
Warning signs and what they mean
| What you see | What it means |
|---|---|
| msiexec.exe outside System32 or SysWOW64, for example in a user folder or Temp | Not the Windows file. A program is borrowing the name. |
| User Account Control shows Publisher: Unknown for msiexec.exe | The file is not Microsoft's. Decline it; accepting lets it make changes to the PC. |
| Copyright line does not say Microsoft Corporation | The file was replaced or is a copy from another source. |
| msiexec.exe running with no installation started by you, or its command line points to a web address | Something is using it to download and run a package; MITRE ATT&CK records this technique. |
| Slowdown, errors, high CPU or odd behaviour together with the signs above | Reported effect of malware using the name; not proof by itself. |
Documented abuse of msiexec.exe
From MITRE ATT&CK technique T1218.007, the public catalogue of attacker techniques. In these cases the genuine file is used to run the attacker's package; the rows quote what the entries observed.
| Malware | How it used the file | Source |
|---|---|---|
| TA505 | Used msiexec to download and execute malicious Windows Installer files. | T1218.007 Msiexec |
| ZIRCONIUM | Used msiexec to download and execute malicious MSI files. | T1218.007 Msiexec |
| Latrodectus | Called msiexec to install remotely hosted MSI files. | T1218.007 Msiexec |
| Duqu | Used msiexec to execute malicious Windows Installer packages. | T1218.007 Msiexec |
| Clop | Can use msiexec.exe to disable security tools on the system. | T1218.007 Msiexec |
| IcedID | Injected itself into suspended msiexec.exe processes for command-and-control communication. | T1218.007 Msiexec |
| QakBot | Can use MSIExec to spawn multiple cmd.exe processes. | T1218.007 Msiexec |
The common pattern is the genuine msiexec.exe running a package the attacker supplied, so the file passes the folder and signature checks. What gives it away is the command line and the package, not the file.
Everyday problems that are not malware
What does the msiexec.exe error "Windows cannot access the specified device, path or file" mean?
The full message reads "C:\Windows\system32\msiexec.exe Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item." It stops programs from installing or uninstalling, and it is usually a permissions or service problem rather than a virus.
Check that the Windows Installer service is available: press Win+R, type services.msc, find Windows Installer, open its Properties and, if the status is Stopped, click Start. Also make sure the .msi file itself is not blocked and that you run it from a folder you have permission to read.
Why is msiexec.exe running when I am not installing anything?
Windows and some programs start it for updates, repairs and configuration, and it exits when finished. If it stays and its command line names a package you do not know, treat it as suspect and check the folder and the command line as described above.
What is mshta.exe, and is it part of msiexec.exe?
mshta.exe is a different Windows file, the Microsoft HTML Application host. It is not part of msiexec.exe. MITRE lists mshta.exe among the system binaries that attackers abuse to run code.
So the two names should be checked separately. Check where each file is and who started it. The genuine files are in C:\Windows\System32.
msiexec.exe versions by Windows release
The newest build indexed for each release, and the update that delivered it. 93 Microsoft builds in total are known.
| Windows release | File version | Delivered by | Size, 64-bit |
|---|---|---|---|
| Windows 11 26H1 | 5.0.28000.2525 | KB5124006, Sep 22, 2026 | 180,224 bytes |
| Windows 11 25H2 | 5.0.26100.5074 | original release | 180,224 bytes |
| Windows 11 24H2 | 5.0.26100.8875 | KB5124010, Sep 22, 2026 | 180,224 bytes |
| Windows 11 23H2 | 5.0.22621.7376 | KB5129242, Sep 14, 2026 | 176,128 bytes |
| Windows 11 22H2 | 5.0.22621.3880 | KB5066793, Oct 14, 2025 | 176,128 bytes |
| Windows 11 21H2 | 5.0.22000.2600 | KB5044280, Oct 8, 2024 | 180,224 bytes |
| Windows 10 22H2 | 5.0.19041.4651 | KB5066198, Sep 25, 2025 | 69,632 bytes |
| Windows 10 21H2 | 5.0.19041.7548 | KB5129236, Sep 14, 2026 | 69,632 bytes |
| Windows 10 21H1 | 5.0.19041.1 | original release | 69,632 bytes |
| Windows 10 20H2 | 5.0.19041.2193 | KB5026361, May 9, 2023 | 103,936 bytes |
Questions people ask
Is msiexec.exe a virus?
No, the file in System32 or SysWOW64 is the genuine Windows Installer. Malware can copy its name, or use the genuine file to run a malicious package. If it is in another folder, or UAC shows an unknown publisher, treat it as not genuine.
Can I delete or end msiexec.exe?
Do not delete the genuine file; Windows needs it to install and remove software. Ending it during an installation makes that installation fail and can leave a half-installed program. Remove only a copy that failed the folder or publisher check, with a full Microsoft Defender scan.
How do I check that my msiexec.exe is real?
Check the file location and the Copyright line. The real file is in C:\Windows\System32 or C:\Windows\SysWOW64 and names Microsoft Corporation. The checker on this page also compares its SHA-256 with the known Microsoft builds, and the command line shows which package it is running.
What does a UAC prompt with an unknown publisher for msiexec.exe mean?
It means the file is not signed by a known publisher, which is not what the Windows file looks like. Decline the prompt. A program run from a crack or keygen often asks for such permission, and accepting it lets the program make changes to the PC, so run a full Microsoft Defender scan afterwards.
How do I remove a fake msiexec.exe?
Decline any prompt that asks for it, then run a full Microsoft Defender scan. If the malware blocks it, restart in Safe Mode, which loads only the drivers and services Windows needs, and scan again, or run the Defender offline scan. Afterwards check that Windows system files are intact with sfc /scannow.
How does the fake file usually get onto a PC?
Often through cracks, keygens and pirated installers from torrent and warez sites, which can run hidden code while the cracked program appears to work. Spam email and malicious websites are other routes. Download software only from the publisher and use an ad blocker on risky sites.
Sources
- Microsoft Learn: msiexec command reference
- MITRE ATT&CK T1218.007: System Binary Proxy Execution, Msiexec
- MITRE ATT&CK: System Binary Proxy Execution, Mshta (T1218.005)
- Winbindex, the Windows binaries index (m417z)
Version data read on Oct 5, 2026.
Questions and experiences
Ask about this page: members and our editors answer. Reading is open; writing needs a free account.
…